Skip to content

Security1 publisher2 min readPublished

Stolen AI session cookies survive a password reset, SOCRadar's exposure report says

SOCRadar tied 5,434 infostealer records for AI tools to 1,500 corporate email addresses at 482 large enterprises. The report says those AI accounts belong under the same sign-on and session controls as a company's identity provider and code repositories.

The Watch · Security desk

Illustration accompanying Stolen AI session cookies survive a password reset, SOCRadar's exposure report says

What happened

  • SOCRadar began with more than one million infostealer records tied to AI services across 80,000-plus corporate domains, then narrowed the set to a large-enterprise sample.
  • Records for 295 of the 482 companies surfaced within the last 90 days.
  • A captured ChatGPT or OpenAI session appears at 358 of the companies, and those companies account for roughly 90% of all records.
  • In late August, Anthropic signed users out, wiped saved payment methods and refunded unauthorized charges after infostealers were used to hijack Claude sessions.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • constraint A password change leaves a replayed AI session signed in, so cleanup after a stealer infection has to include ending the user's sessions on each AI platform.
  • exposure Standing OAuth grants let a stolen Zapier session reach CRM, email and storage, and a scheduled exfiltration workflow built there runs from the vendor's trusted IP space.
  • cost The victim company pays for LLMjacking: API keys lifted from notes apps and workspace settings are billed to its account or resold as discounted access.
  • precedent Claude sits outside the top ranks because it has a smaller corporate footprint, per the report, so its share of stealer logs should rise as more companies adopt it.

Whoever buys a stealer log with an AI session cookie in it holds a live login [9]. Replaying the cookie puts them inside the account past MFA, with no password prompt [9]. Okta's Jeremy Kirk has made the same point: session tokens and API keys are sought out because they can be replayed to bypass credential-based authentication [10].

The first thing a buyer gets is the history. Employees paste source code, customer records, contracts and unreleased plans into prompts, and the report says a replayed session hands that archive over before the attacker touches an internal system [12].

Getting in costs very little. The report's own list is one employee, one unmanaged laptop, one saved ChatGPT password and one commodity infostealer that has been on sale in Telegram channels since 2022 [17]. This is the commodity stealer trade at work, with AI sessions added to what it harvests [17].

The figures are SOCRadar's own. The published account includes a pitch for the company's free domain check, which it says needs no signup and updates daily across 44 AI platforms [19]. The sample leans large: 68% of the 482 companies are billion-dollar organizations, spread across 36 countries and eight sectors and concentrated in North America [2]. The records work out to about 3.6 per exposed email address [1].

Technology and internet-services firms are the largest group, 144 companies with 40% of all records [15]. Roughly 30% of the sample therefore holds 40% of the records [2], and those firms hold data for many downstream clients [15]. LLM-platform exposure is near-universal and peaks in energy, at 93% of affected companies [16]. Agent and automation exposure, the kind that carries an employee's authority into other systems, clusters in healthcare, financial services and technology [16].

Developer platforms are in the data. The report does not give company counts for Hugging Face or Replit; it lists them with Zapier, Notion, Lovable and ElevenLabs as trailing far behind ChatGPT [6].

What to watch

  • Whether OpenAI answers stealer-driven session theft with forced sign-outs and refunds on the scale Anthropic used in August.
  • Whether AI vendors give employers a way to revoke an employee's sessions centrally through SSO, the step a password reset leaves undone.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories